Skip to content
ToolShedby Wasim Shaikh

JWT Decoder

Decode a JSON Web Token to read its header and payload, see when it expires, and verify HS256/384/512 signatures. Runs entirely in your browser.

Examples:

eyJhbGciOiJIUzI1NiIsInR5cCI6IkpXVCJ9.eyJzdWIiOiIxMjM0NTY3ODkwIiwibmFtZSI6IkFzaGEgUGF0ZWwiLCJlbWFpbCI6ImFzaGFAZXhhbXBsZS5jb20iLCJyb2xlcyI6WyJlZGl0b3IiXSwiaWF0IjoxNzYwMDAwMDAwLCJleHAiOjQxMDI0NDQ4MDB9.Ffhu5dYsDXsjDSFpu8wvKm_m_32PoVfRRyVhtwRuwKE

Header

ClaimValue
algSigning algorithmHS256
typToken typeJWT

Payload

ClaimValue
subSubject: the user or entity the token is about1234567890
nameFull nameAsha Patel
emailEmail addressasha@example.com
rolesRoles assigned to the subject["editor"]
iatIssued at1760000000Oct 9, 2025, 8:53:20 AM UTC
expExpiration time4102444800Jan 1, 2100, 12:00:00 AM UTC

Signature

Enter the shared secret to check the HS256 signature. The check runs in your browser with the Web Crypto API. The demo tokens use .

Ffhu5dYsDXsjDSFpu8wvKm_m_32PoVfRRyVhtwRuwKE

What Is a JWT?

A JSON Web Token (JWT, defined in RFC 7519) is a compact, URL-safe string used to pass identity and permissions between systems, most often as an OAuth 2.0 access token or an OpenID Connect ID token. It has three parts separated by dots, each base64url encoded:

  • Header: JSON describing the token: the signing algorithm (alg), the type (typ) and often the key ID (kid).
  • Payload: JSON "claims" about the user and the token, such as sub, iss, aud and the exp expiry time.
  • Signature: Proves the header and payload were not changed. It is created with a secret (HS256) or a private key (RS256, ES256).

Registered Claims

ClaimNameMeaning
issIssuerWho created the token, usually your identity provider’s URL
subSubjectThe user or service the token is about
audAudienceWhich API or app should accept the token
expExpirationAfter this time the token must be rejected
nbfNot beforeBefore this time the token must be rejected
iatIssued atWhen the token was created
jtiJWT IDA unique ID, used to stop the same token being replayed

How to Decode a JWT

  1. Paste the token, or a whole Authorization: Bearer … header.
  2. Read the header and payload as a claims table or as formatted JSON, and copy either one.
  3. Check the status: whether the token has expired or is not valid yet, with dates in your local time.
  4. Verify the signature of an HS256, HS384 or HS512 token by entering its secret.

Frequently Asked Questions

Is it safe to paste my JWT here?
The decoder runs entirely in your browser and the token is never sent to a server. Even so, a live access token works like a password until it expires, so prefer test tokens and never share production tokens in screenshots or tickets.
Does decoding a JWT verify it?
No. The header and payload are only base64url encoded, so anyone can read them. A token is trustworthy only after your server checks the signature, the expiry (exp and nbf), the issuer (iss) and the audience (aud). This tool can check HS256, HS384 and HS512 signatures if you enter the shared secret.
Are JWTs encrypted?
Normal signed tokens (JWS, three parts) are not encrypted, so never put passwords or other secrets in the payload. Encrypted tokens (JWE) have five parts; this tool shows their header but cannot read the payload without the key.
What format are exp, iat and nbf in?
They are "NumericDate" values: the number of seconds since 1 January 1970 UTC. The decoder converts them to your local time and shows how long ago or how soon they are. A value in milliseconds is a common bug, and the tool warns about it.
Why can’t I verify an RS256 or ES256 token here?
Those tokens are signed with a private key and checked with the issuer’s public key, usually published at a JWKS URL. Use your JWT library on the server for that check; this page decodes them and shows the signature.
What does "alg": "none" mean?
The token has no signature at all. Servers must never accept unsigned tokens, and RFC 8725 recommends that libraries only allow the algorithms you expect. The decoder flags these tokens with a warning.
Can I paste a whole Authorization header?
Yes. A leading "Authorization:" or "Bearer " and any surrounding quotes or spaces are removed before decoding.

Sources & Standards

Claim names and validation advice follow the IETF and OpenID specifications below. Last reviewed .

Decoding other encodings? Try the Base64 Decoder or the URL Decoder.

Related Tools